HomeSubjectsUniversityBlogAbout

Security Engineering

Topic in Software Engineering

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Security engineering is the practice of building software that keeps confidentiality, integrity and availability intact even when attackers try to misuse it. Questions cover common vulnerabilities from the OWASP Top 10, such as SQL injection, cross-site scripting and broken authentication, along with their defences like parameterised queries and input validation. Threat modelling with STRIDE (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege) is a recurring theme. Expect static versus dynamic application security testing (SAST and DAST), secure session management, firewalls and denial-of-service attacks, maturity models like SAMM, why security by obscurity fails, and software supply chain security.

Below are 30 practice questions from a pool of 210 Security Engineering MCQs, one of 16 topics in Software Engineering. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Security EngineeringEasy

Q1. What is a vulnerability in software?

  1. A.A software defect fix and patch release and update
  2. B.A specific automated test case and scenario and script
  3. C.An intended software feature and product capability
  4. D.A weakness that can be exploited to compromise security✓ Correct

Explanation

A vulnerability is a weakness that can be exploited by threats.

Report an error in this question

Security EngineeringEasy

Q2. What is encryption?

  1. A.Authentication in the engineering discipline for effective project outcomes
  2. B.Converting data into a coded form to prevent unauthorized access✓ Correct
  3. C.Compression in all development efforts by the project team members
  4. D.Decryption and related components to achieve project objectives

Explanation

Encryption transforms data into an unreadable format using an algorithm and key.

Report an error in this question

Security EngineeringEasy

Q3. What is a firewall?

  1. A.A type of computer virus or malware threat and attack during implementation
  2. B.A general-purpose programming language tool and system for quality purposes
  3. C.A physical wall constructed of fire bricks and mortar in the system context
  4. D.A network security device that monitors and controls incoming and outgoing traffic✓ Correct

Explanation

A firewall monitors and filters network traffic based on security rules.

Report an error in this question

Security EngineeringEasy

Q4. What is a security threat?

  1. A.A scheduled software update release event and launch as part of the methodology
  2. B.A formal source code peer review session and meeting during the software lifecycle
  3. C.A potential cause of an unwanted incident that may result in harm to a system✓ Correct
  4. D.A new feature request from stakeholders and clients in the development process

Explanation

A security threat is a potential danger that might exploit a vulnerability.

Report an error in this question

Security EngineeringEasy

Q5. What is cross-site scripting (XSS)?

  1. A.An attack where malicious scripts are injected into web pages viewed by other users✓ Correct
  2. B.A JavaScript library for DOM manipulation and events throughout the project
  3. C.A CSS framework for styling web content and layouts for the development team
  4. D.A source code implementation coding technique and tool within the project scope

Explanation

XSS injects malicious scripts into web pages viewed by other users.

Report an error in this question

Security EngineeringEasy

Q6. What is authentication?

  1. A.Verifying the identity of a user or system✓ Correct
  2. B.Encryption within the system boundary
  3. C.Firewall configuration by the development process
  4. D.Authorization according to best practices

Explanation

Authentication verifies that a user or system is who they claim to be.

Report an error in this question

Security EngineeringEasy

Q7. What is SQL injection?

  1. A.A database installation and setup procedure and guide
  2. B.An attack that inserts malicious SQL code into application queries✓ Correct
  3. C.A scheduled database backup and restore job and task
  4. D.A standard SQL database query feature and capability

Explanation

SQL injection inserts malicious SQL into input fields to manipulate queries.

Report an error in this question

Security EngineeringEasy

Q8. What is authorization?

  1. A.Encryption over the entire lifecycle as defined by standards
  2. B.Authentication and its related activities
  3. C.Determining what permissions an authenticated user has✓ Correct
  4. D.Decryption for all project stakeholders within the given

Explanation

Authorization determines what an authenticated user is permitted to access.

Report an error in this question

Security EngineeringEasy

Q9. What is software security?

  1. A.Locking the physical computer server room and door across all phases
  2. B.Using strong passwords for user accounts only ever for the project goals
  3. C.Protecting software from unauthorized access, use, modification, and destruction✓ Correct
  4. D.Installing antivirus software applications only ever in a systematic way

Explanation

Software security protects against unauthorized access and malicious attacks.

Report an error in this question

Security EngineeringEasy

Q10. What is HTTPS?

  1. A.A general-purpose programming language type and tool in practice typically
  2. B.A specific type of database storage system and service as a standard approach
  3. C.A comprehensive software testing framework and tool set by the organization
  4. D.HTTP Secure — a protocol for secure communication over a network using encryption✓ Correct

Explanation

HTTPS uses TLS/SSL encryption to protect data in transit.

Report an error in this question

Security EngineeringMedium

Q11. What is defense in depth?

  1. A.A security approach using multiple layers of security controls throughout a system✓ Correct
  2. B.Defending only the database from attacks and threats within the given constraints
  3. C.Having one single strong defense mechanism and barrier for all project stakeholders
  4. D.A military strategy used only in warfare and battles as defined by standards

Explanation

Defense in depth uses multiple security layers for protection.

Report an error in this question

Security EngineeringMedium

Q12. What is input validation?

  1. A.Accepting all user input without any validation checks by the development process
  2. B.Validating only system output and response data values and its related activities
  3. C.Testing user interface elements for usability and flow over the entire lifecycle
  4. D.Checking and sanitizing user input to prevent malicious data from entering the system✓ Correct

Explanation

Input validation prevents malicious data from entering the system.

Report an error in this question

Security EngineeringMedium

Q13. What is the OWASP Top 10?

  1. A.A popular music chart and ranking system and listing
  2. B.A list of the ten most critical web application security risks✓ Correct
  3. C.An established coding standard and guideline and rule
  4. D.A comprehensive software testing framework tool and set

Explanation

The OWASP Top 10 lists the most critical web application security risks.

Report an error in this question

Security EngineeringMedium

Q14. What is a buffer overflow?

  1. A.Having too much data stored in a buffer data area for the project goals
  2. B.A database table overflow and storage issue and error within the system boundary
  3. C.A vulnerability where data written beyond a buffer's boundary can overwrite adjacent memory✓ Correct
  4. D.A network traffic overflow and congestion issue event according to best practices

Explanation

Buffer overflow overwrites adjacent memory, potentially enabling code execution.

Report an error in this question

Security EngineeringMedium

Q15. What is the CIA triad in security?

  1. A.A government intelligence agency abbreviation and name as part of the methodology
  2. B.An established coding standard and guideline and rule set in the development process
  3. C.Confidentiality, Integrity, and Availability — the three core principles of information security✓ Correct
  4. D.A comprehensive software testing framework and tool suite during the software lifecycle

Explanation

CIA triad: Confidentiality, Integrity, and Availability.

Report an error in this question

Security EngineeringMedium

Q16. What is secure coding?

  1. A.Writing code in a physically secure room and building
  2. B.Encrypting all application source code files and folders
  3. C.Development practices that protect software from security vulnerabilities✓ Correct
  4. D.Using complex passwords directly in application code

Explanation

Secure coding prevents the introduction of security vulnerabilities.

Report an error in this question

Security EngineeringMedium

Q17. What is penetration testing?

  1. A.Physical building break-in testing attempt and effort
  2. B.Database query performance testing and benchmarking
  3. C.Network communication speed testing and measurement
  4. D.Simulating cyberattacks to identify security vulnerabilities in a system✓ Correct

Explanation

Penetration testing simulates real-world cyberattacks.

Report an error in this question

Security EngineeringMedium

Q18. What is a denial-of-service (DoS) attack?

  1. A.A specific type of computer virus or malware and threat in the engineering discipline
  2. B.Denying customer service requests politely and kindly to achieve project objectives
  3. C.An attack that overwhelms a system with traffic to make it unavailable to users✓ Correct
  4. D.A network configuration and setup procedure and process for effective project outcomes

Explanation

DoS floods a system with traffic to make it unavailable.

Report an error in this question

Security EngineeringMedium

Q19. What is a security audit?

  1. A.A financial accounting audit process and procedure type in all development efforts
  2. B.A systematic evaluation of a system's security by examining compliance with security policies✓ Correct
  3. C.A system performance load test execution and run process and related components
  4. D.A formal source code peer review session and process only by the project team members

Explanation

A security audit evaluates compliance with security standards.

Report an error in this question

Security EngineeringMedium

Q20. What is the principle of least privilege?

  1. A.Maximum access permissions for all system users always across all phases
  2. B.No access permissions for any user in the system ever in a systematic way
  3. C.Users should only have the minimum access rights necessary to perform their tasks✓ Correct
  4. D.Giving everyone full administrator access to everything at every stage

Explanation

Least privilege grants only the minimum permissions needed.

Report an error in this question

Security EngineeringHard

Q21. What is threat modeling?

  1. A.Creating detailed threat assessment reports and summaries for the development team
  2. B.A systematic approach to identifying, quantifying, and addressing security threats to a system✓ Correct
  3. C.Modeling threats in three-dimensional space and models within the project scope
  4. D.A specific type of software testing approach and method throughout the project

Explanation

Threat modeling systematically identifies threats and designs countermeasures.

Report an error in this question

Security EngineeringHard

Q22. What is a zero-day vulnerability?

  1. A.A vulnerability that is only one day old at most today within the system boundary
  2. B.A previously unknown vulnerability that is exploited before a patch is available✓ Correct
  3. C.A vulnerability with absolutely zero impact on the system according to best practices
  4. D.A vulnerability that was fixed on day zero of discovery for the project goals

Explanation

A zero-day is exploited before the developer can create a patch.

Report an error in this question

Security EngineeringHard

Q23. What is the STRIDE threat model?

  1. A.A source code implementation coding framework and library for quality purposes in practice typically
  2. B.A comprehensive software testing model and approach only as a standard approach by the organization
  3. C.A threat classification model: Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege✓ Correct
  4. D.A physical walking gait analysis technique and method in the system context during implementation

Explanation

STRIDE classifies threats into six categories.

Report an error in this question

Security EngineeringHard

Q24. What is a Common Vulnerabilities and Exposures (CVE)?

  1. A.A standardized system for identifying and naming publicly known cybersecurity vulnerabilities✓ Correct
  2. B.A comprehensive software testing framework and tool suite for effective project outcomes
  3. C.An established coding standard and guideline and rule set in the engineering discipline
  4. D.A specific type of computer virus or malware and threat to achieve project objectives

Explanation

CVE is a dictionary of publicly known vulnerabilities with unique identifiers.

Report an error in this question

Security EngineeringHard

Q25. What is the concept of 'security by design'?

  1. A.Integrating security considerations into every phase of the software development lifecycle✓ Correct
  2. B.Designing security logos and brand imagery and assets at every stage
  3. C.Adding security features only after deployment to production across all phases
  4. D.Writing security documentation exclusively and nothing else in a systematic way

Explanation

Security by design incorporates security from the earliest development stages.

Report an error in this question

Security EngineeringHard

Q26. What is the concept of 'attack surface'?

  1. A.The physical surface of a computer case and housing as part of the methodology
  2. B.A network configuration and topology setup and structure during the software lifecycle
  3. C.A specific type of user interface design and layout only in the development process
  4. D.The total number of points where an unauthorized user can try to enter or extract data✓ Correct

Explanation

Attack surface is the sum of all possible entry and extraction points.

Report an error in this question

Security EngineeringHard

Q27. What is the DREAD risk assessment model?

  1. A.A comprehensive software testing model and approach only and its related activities
  2. B.An established coding standard and guideline and rule set over the entire lifecycle
  3. C.An assessment of fear and dread feelings and emotions by the development process
  4. D.A model rating threats by Damage, Reproducibility, Exploitability, Affected users, Discoverability✓ Correct

Explanation

DREAD rates threats across five dimensions.

Report an error in this question

Security EngineeringHard

Q28. What is secure software development lifecycle (SSDLC)?

  1. A.A comprehensive software testing lifecycle and approach for all project stakeholders
  2. B.A production deployment lifecycle plan and schedule doc within the given constraints
  3. C.An approach that integrates security practices into each phase of the traditional SDLC✓ Correct
  4. D.A brand new programming language created from scratch as defined by standards

Explanation

SSDLC integrates security activities into every development phase.

Report an error in this question

Security EngineeringHard

Q29. What is the difference between symmetric and asymmetric encryption?

  1. A.Asymmetric encryption uses only one single key for all by the project team members
  2. B.The two encryption types are fundamentally the same thing in all development efforts
  3. C.Symmetric encryption uses two different keys always now and related components
  4. D.Symmetric uses the same key for encryption and decryption; asymmetric uses a key pair✓ Correct

Explanation

Symmetric uses one key; asymmetric uses a public-private key pair.

Report an error in this question

Security EngineeringHard

Q30. What is the principle of 'fail secure' vs 'fail open'?

  1. A.The two concepts are fundamentally identical in all ways within the project scope
  2. B.Fail secure allows all access on any failure or error event throughout the project
  3. C.Fail open is always the more secure approach and method for the development team
  4. D.Fail secure denies access by default on failure; fail open allows access on failure✓ Correct

Explanation

Fail secure denies access on failure; fail open allows it.

Report an error in this question

Ready to test yourself on Security Engineering?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Security Engineering Quiz